Data Availability Services
Vendor:
First CVE: Jul 26, 2019 · Active for 6 years
61
Total CVEs
More Total CVEs than 98% of tracked products
30.5
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 21% of tracked products
3.3%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Data Availability Services over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 26, 2019
6 years ago
Most Recent CVE
Feb 25, 2020
2,341 days ago
CVE Severity & Scoring
Data Availability Services61 CVEs
57%
36%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local29 (47.5%)
Network15 (24.6%)
Unknown0 (0.0%)
Physical16 (26.2%)
Adjacent Network1 (1.6%)
Attack Complexity
Low55 (90.2%)
High6 (9.8%)
Unknown0 (0.0%)
User Interaction
None56 (91.8%)
Unknown0 (0.0%)
Required5 (8.2%)
Privileges Required
Low23 (37.7%)
High2 (3.3%)
None36 (59.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (61 CVEs).
61 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-1938CRITICAL When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for e | Feb 24, 2020 | 9.8 | 99 | YES | YES |
CVE-2019-2215HIGH A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploi | Oct 11, 2019 | 7.8 | 96 | YES | YES |
CVE-2020-5398HIGH In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (R | Jan 17, 2020 | 7.5 | 73 | NO | NO |
CVE-2019-18805CRITICAL An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in tcp_ack_update_rtt() when usersp | Nov 7, 2019 | 9.8 | 31 | NO | NO |
CVE-2019-14821HIGH An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor implements the Coalesced MMIO write operation. It op | Sep 19, 2019 | 8.8 | 28 | NO | NO |
CVE-2019-5108MEDIUM An exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3. An attacker could exploit this vulnerability by triggering AP to send IAPP location | Dec 23, 2019 | 6.5 | 27 | NO | NO |
CVE-2019-19816HIGH In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image and performing some operations can cause slab-out-of-bounds write access in __btrfs_map_block in fs/btrfs/volu | Dec 17, 2019 | 7.8 | 26 | NO | NO |
CVE-2019-19447HIGH In the Linux kernel 5.0.21, mounting a crafted ext4 filesystem image, performing some operations, and unmounting can lead to a use-after-free in ext4_put_super in fs/ext4/super.c, | Dec 8, 2019 | 7.8 | 26 | NO | NO |
CVE-2019-19052HIGH A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption) by | Nov 18, 2019 | 7.5 | 26 | NO | NO |
CVE-2019-15538HIGH An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on account of being out of disk quota | Aug 25, 2019 | 7.5 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (61 CVEs).
CISA KEV
2 CVEs
3.3% of CVEs· 97th percentile
Metasploit
2 CVEs
3.3% of CVEs· 96th percentile
Nuclei
1 CVE
1.6% of CVEs· 96th percentile
ExploitDB
2 CVEs
3.3% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (61 CVEs).
Media Mentions
Signals from CVEs in this product scope (61 CVEs).
Top CNAs Publishing CVEs For Data Availability Services
Top CWEs
Versions
No cataloged versions.